Cyber Dispatch™️
394 subscribers
33 photos
2 videos
49 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Proton has launched a free tool that shows users how much personal information ChatGPT and Claude may reveal through their conversation histories, highlighting the privacy risks of repeatedly sharing sensitive information with AI chatbots.

Called AI Paper Trail, the tool analyzes exported conversation data from OpenAI's ChatGPT or Anthropic's Claude and generates a personalized report detailing what can be inferred from a user's chats. Proton said even seemingly harmless conversations can accumulate into a detailed profile covering a person's work, relationships, identity, habits, and personal interests.
Philips and GE investigating Clop ransomware data theft claims.
McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen.
Microsoft working on Defender patch for ShieldBreak zero-day.

Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass.
The British government has launched a pilot program to train up to 70 young people aged 16-21 in artificial intelligence in Northwest England. This three-week program, in addition to teaching the responsible development and use of AI tools, also provides training in essential work skills such as communication, teamwork, organization, and problem-solving.
Goldman Sachs is in talks with financial institutions to participate in Nvidia's $500 billion project to develop AI infrastructure.
Cybersecurity experts have warned that AI tools and low-code/no-code platforms have made it easier, even for inexperienced individuals, to create audio and video deepfakes.
Critical Vulnerability Found in Smartphones with Unisoc Chipsets

Researchers have identified a vulnerability in the modems of certain Unisoc chipsets, which are used in a number of Android phones. An attacker can send malicious SIP/VoLTE messages during a video call, and if the victim responds, the attacker can gain access to the device's memory by processing these messages.
Google has introduced the new Gemini 3.7 Flash model, focusing on coding, web development, and performing tasks based on AI agents.
Critical GitLab vulnerability could let unauthenticated attackers delete public projects.

CVE-2026-19478 affects self-managed CE and EE under certain conditions. Fixes are in 19.2.4, 19.1.6, 19.0.8, and 18.11.11.
Yesterday GitHub went down for 7 and a half hours. Website, Actions, Copilot, code merging, all of it. 15,000 developers reported outage.

GitHub's own CTO admitted they planned for 10x capacity and realized they needed 30x. They're now renting servers from AWS, Microsoft's biggest cloud rival.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced that ransomware groups are exploiting the CVE-2025-60710 vulnerability in the Windows Task Host component.
Microsoft has begun removing the legacy WMIC tool from new versions of Windows 11. This tool was used for years to manage and execute system commands, but cyber attackers also used it to carry out malicious activities.

Hackers could exploit WMIC to identify or bypass certain security features of the system, and even disable data recovery capabilities in ransomware attacks.
Massive Cyberattack Targets French Ministry of Education

The French Ministry of Education has been the target of a cyberattack, and investigations are ongoing to determine the extent of the incident.

#TGITM @TheGhostITM
Home Wi‑Fi Routers Now Track Motion

By The Ghost In The Machine

Comcast’s new WiFi Motion feature is drawing attention for what it reveals about the modern home: even without cameras, a network can still detect whether people are present, moving, or asleep. By analyzing subtle changes in Wi‑Fi signals, the system can infer occupancy patterns and activity inside a household. Comcast says the feature does not record images or directly identify individuals, but the privacy implications are hard to ignore.

The technology may be marketed as convenient, but it also exposes a deeper concern about surveillance built into ordinary consumer devices. A system that can tell when someone is home can also create a detailed picture of daily routines. That information is sensitive on its own, and it becomes even more concerning if the modem or connected account is compromised.

Security researchers have long shown that wireless signals can reveal more than many users expect. The same data used to detect presence can, in the wrong hands, become a tool for monitoring household behavior. If a criminal were able to access the system, occupancy details could potentially help identify when a home is empty or when residents are least active. That makes protection of the device and account essential.

The issue is not limited to Comcast. It reflects a wider trend in smart-home technology, where convenience often advances faster than public understanding of the risks. Consumers are increasingly asked to trust that opaque systems will collect only what is necessary and store it responsibly. But when those systems can infer intimate details about everyday life, trust alone is not enough.

Any company offering this kind of feature should provide clear disclosure, strong default security, and an easy opt-out. Homeowners deserve to know not just what data is captured, but what can be inferred from it. In the age of connected living, privacy is no longer only about cameras and microphones. Sometimes, the most revealing device in the home is the router.

#TGITM
Thirty US states are suing Meta for over $1 trillion, accusing it of knowingly designing Instagram and Facebook to be addictive and harmful to children, while concealing what it knew.

If they win, it could force Meta to overhaul the platforms for good, ending features like "like" counts, infinite scroll and autoplay video.
Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia.
ECUADOR: Hacker Claims 20M+ Health Ministry Database Records, Offers 73GB Dataset for Sale.
🐧 Linux Kernel 7.2 Officially Released

Linux 7.2 has officially been released and is now the latest mainline version of the Linux kernel.
ARGENTINA: Access to Municipal Government System Allegedly Offered for Sale

Hacker is advertising alleged unauthorized access to an Argentine municipal government environment associated with a .gob.ar domain.
UAE: College Website Allegedly Breached, Databases and Source Code Leaked

Hacker claims to have compromised https://tahoor.ae, described in the underground forum post as a college website affiliated with Jawaharlal Nehru Technological University.